The isRowProducer comment now says it matches method names only and
names the evasion that follows: a repo-local Row or QueryRow helper
returning *gorm.DB gets past it. GORM's Rows is dropped from those
names: it also returns an error, so Scan is never called on its result
directly. unguardedScans states method values (f := db.Scan) as out of
scope, with the reason. The 40-file floor is replaced by a check that
static, templates and every directory under cmd and internal was
walked, so skipping a whole package fails the test. The planted
snippets cover the struct-field receiver and each accepted row
producer, and are all valid Go inside a wrapper that declares the names
they use. The stale "one caller" sentence is dropped.
Model: opus-5-5